Malware

Malware.AI.863056352 information

Malware Removal

The Malware.AI.863056352 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.863056352 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.863056352?


File Info:

crc32: CBB597A2
md5: 44031bb45e2efc9b723111843f4efa37
name: 44031BB45E2EFC9B723111843F4EFA37.mlw
sha1: 219b9d6f478e46cb7d4c47fdb700e40c3998a7ef
sha256: 5f37c665cf5c07f394a793aa94cea479fd5f1301d5e8d48f5cdafeda6023f8d3
sha512: ae1a4818eb13aaccda4476bb04482ec54e59eb250cab04c59e152a3c252739c06f31c9558e0636f90bce58c5e7836672893158d627d7ac9703ec39353886b81c
ssdeep: 12288:K1xkYq/2Jtg8rkqRV845mxXuK7L+XZ/vvQ+9M12qar:qxkYHtg8gElmxxEmqr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Assembly Version: 6.8.30.3
LegalCopyright: (C)Selteco 2007-2015
InternalName: PullingInvocation
FileVersion: 6.8.30.3
CompanyName: Selteco
PrivateBuild: 6.8.30.3
LegalTrademarks: (C)Selteco 2007-2015
Comments: Hagd Update Unrealistic Cockburn Vertically
ProductName: PullingInvocation
Languages: English
ProductVersion: 6.8.30.3
FileDescription: Hagd Update Unrealistic Cockburn Vertically
OriginalFilename: PullingInvocation
Translation: 0x0409 0x04b0

Malware.AI.863056352 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Foreign.tqE5
Elasticmalicious (high confidence)
DrWebWin32.HLLM.Reset.493
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.378851
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.57708
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.45e2ef
CyrenW32/Foreign.P.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.FSWJ
APEXMalicious
AvastWin32:Ramnit-AR
ClamAVWin.Dropper.Ramnit-7076512-0
KasperskyTrojan-Ransom.Win32.Foreign.njmq
BitDefenderGen:Variant.Zusy.378851
NANO-AntivirusTrojan.Win32.Reset.ezpnkc
MicroWorld-eScanGen:Variant.Zusy.378851
TencentMalware.Win32.Gencirc.10c8bed5
Ad-AwareGen:Variant.Zusy.378851
SophosMal/Generic-S
ComodoVirus.Win32.Ramnit.GENV@4roe85
BitDefenderThetaGen:NN.ZexaF.34266.Mq0@a4QyQ1gi
VIPREVirus.Win32.Nimnul.ea (v)
McAfee-GW-EditionGenericRXER-UF!44031BB45E2E
FireEyeGeneric.mg.44031bb45e2efc9b
EmsisoftGen:Variant.Zusy.378851 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.gdf
AviraW32/Nimnul.D
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASVirus.2CA
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Zusy.D5C7E3
GDataGen:Variant.Zusy.378851
McAfeeGenericRXER-UF!44031BB45E2E
MAXmalware (ai score=99)
VBA32Trojan-Ransom.Foreign
MalwarebytesMalware.AI.863056352
PandaTrj/Genetic.gen
RisingVirus.Ramnit!1.A1AD (CLASSIC)
IkarusVirus.Win32.Ramnit
FortinetW32/Kryptik.FNNB!tr
AVGWin32:Ramnit-AR
Paloaltogeneric.ml

How to remove Malware.AI.863056352?

Malware.AI.863056352 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment